CVE-2026-68148: fscrypt: Add missing superblock check in find_or_insert_direct_key()

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081001-CVE-2026-68148-7d8c@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

fscrypt: Add missing superblock check in find_or_insert_direct_key()

The legacy 'fscrypt_direct_keys' table caches master keys that are used
by v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY.
It's just a global table for all filesystems (since the keys can be
provided by the legacy process-subscribed keyrings mechanism, which
makes it difficult to reuse super_block::s_master_keys).

The entries in it ('struct fscrypt_direct_key') do contain a super_block
pointer, though, for passing to fscrypt_destroy_inline_crypt_key() when
the last inode that references the key is evicted.

However, when finding the fscrypt_direct_key for an inode, we weren't
actually comparing the super_block pointer.  As a result, inodes with
different super_blocks could point to the same fscrypt_direct_key.  That
could extend the lifetime of a fscrypt_direct_key beyond the
super_block it points to, causing a use-after-free later.

Fix this by creating distinct fscrypt_direct_key structs for distinct
super_block structs.

Note that this problem doesn't exist in the v2 policy equivalent
("per-mode keys"), since the data structures there are per super_block.

The Linux kernel CVE team has assigned CVE-2026-68148 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 6.6.148 with commit 330249609b70778094a7a36f5b6bcfa6362121d4
	Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 6.12.101 with commit deff41898a5ae3a47db5fa1896a494aa95efda5d
	Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 6.18.42 with commit 95376fe9c145be35566991df99c53134943d992f
	Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 7.1.6 with commit 466f187b501a5ac8e1ea2ccf3ccd5c46108d8830
	Issue introduced in 6.1 with commit 22e9947a4b2ba255888541bd0111cf00b9b16586 and fixed in 7.2-rc5 with commit b5fa40226e71c17847b9ff2816c6ca4133d0d994

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-68148
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/crypto/keysetup_v1.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/330249609b70778094a7a36f5b6bcfa6362121d4
	https://git.kernel.org/stable/c/deff41898a5ae3a47db5fa1896a494aa95efda5d
	https://git.kernel.org/stable/c/95376fe9c145be35566991df99c53134943d992f
	https://git.kernel.org/stable/c/466f187b501a5ac8e1ea2ccf3ccd5c46108d8830
	https://git.kernel.org/stable/c/b5fa40226e71c17847b9ff2816c6ca4133d0d994
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.